Aug 27, 2026

Texas Biometric Privacy and Data Security

General Educational Information — For Educational Purposes Only, Not Professional Advice.

Smart Business Blueprint is not a law firm or accounting firm and does not provide tax, legal, or accounting services.

Laws change frequently and may differ based on individual circumstances.

Get Updates on New Texas Business Guides

Texas businesses face obligations under several overlapping privacy and data-security laws, including the Texas Data Privacy and Security Act, Texas's data breach notification law, and the Capture or Use of Biometric Identifier Act (CUBI). This guide covers all three, along with the industry-specific rules that often apply on top of them.

Quick Answer

  • The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, is Texas's comprehensive consumer data privacy law and applies to covered businesses that meet the statute's applicability requirements, subject to exemptions.
  • Texas requires notice to affected individuals within 60 days of determining a data breach occurred.
  • Breaches affecting 250 or more Texas residents also require notice to the Texas Attorney General within 30 days.
  • The Capture or Use of Biometric Identifier Act (CUBI) requires notice and consent before capturing biometric identifiers for a commercial purpose.
  • CUBI violations carry civil penalties of up to $25,000 per violation, enforced exclusively by the Texas Attorney General.
  • Healthcare, financial services, and businesses that accept payment cards may face additional obligations under HIPAA, GLBA, and applicable PCI DSS standards.

Key Takeaways

  • Texas's comprehensive privacy law, the TDPSA, is codified at Business and Commerce Code Chapter 541 and took effect July 1, 2024.
  • Small businesses (as defined by the U.S. Small Business Administration) are generally exempt from the TDPSA, but must still get consent before selling sensitive data.
  • Texas's data breach law is codified at Business and Commerce Code Section 521.053.
  • The individual-notification deadline is 60 days; the Attorney General deadline (250+ residents) is 30 days.
  • As of September 2023, AG breach notifications must be submitted electronically through the Attorney General's website.
  • CUBI defines biometric identifiers narrowly: retina/iris scans, fingerprints, voiceprints, and hand or face geometry records.
  • Businesses must destroy captured biometric identifiers within a reasonable time, and no later than the first anniversary of the date the purpose for collecting them expires, subject to statutory exceptions.
  • Financial institution voiceprint data is exempt from CUBI, and GLBA-regulated entities are generally exempt from the TDPSA.
  • Neither CUBI nor the TDPSA provides a private right of action under the statute. The Texas Attorney General has enforcement authority under both laws.
  • An incident response plan prepared before a breach occurs significantly reduces the risk of missing statutory deadlines.

1. Texas's Data Security Legal Landscape

Texas businesses face obligations under several overlapping privacy and data-security laws. The Texas Data Privacy and Security Act governs how businesses collect, use, and sell Texas consumers' personal data generally. Layered on top of that are two more specific obligations: notifying people after a data breach, and getting consent before capturing biometric identifiers for commercial purposes.

These three frameworks — the TDPSA, the breach notification law, and CUBI — often apply simultaneously to the same business, and each carries its own deadlines and requirements.

2. The Texas Data Privacy and Security Act

The Texas Data Privacy and Security Act (TDPSA), codified at Texas Business and Commerce Code Chapter 541, is Texas's comprehensive consumer data privacy law. It was enacted through House Bill 4 during the 88th Texas Legislative Session and took effect July 1, 2024.

The TDPSA generally applies to any person or business that conducts business in Texas or produces products or services consumed by Texas residents, processes or sells personal data, and does not qualify as a small business under the U.S. Small Business Administration's size standards, subject to the statute's other applicability and exemption provisions. Unlike many other state privacy laws, the TDPSA does not set a minimum revenue or consumer-count threshold — coverage is instead based primarily on the small-business exemption and the entity- and data-level exemptions described below.

The TDPSA grants Texas consumers several rights over their personal data, including the right to access, correct, delete, and opt out of the processing of their data for purposes such as targeted advertising or sale. It requires covered businesses to provide clear privacy notices and implement reasonable data security practices, and imposes additional consent requirements before processing certain categories of sensitive data, including biometric data.

Small Business Exemption

Small businesses, as defined by the SBA, are generally exempt from the TDPSA — but even an exempt small business must still obtain consumer consent before selling sensitive personal data.

Entity-Level Exemptions

The TDPSA exempts certain entities outright, including state agencies, nonprofits, institutions of higher education, and entities regulated under HIPAA or the Gramm-Leach-Bliley Act.

Enforcement

The TDPSA is enforced exclusively by the Texas Attorney General. It does not create a private right of action, meaning individual consumers cannot sue directly under the statute.

Note A provision allowing consumers to direct an authorized agent to submit opt-out requests through recognized universal opt-out technology (such as browser-level signals) took effect separately on January 1, 2025.
The TDPSA sits alongside — not instead of — CUBI and the breach notification law: a business can be subject to all three at once for the same set of data practices.

3. The Texas Data Breach Notification Law

Texas's breach notification requirements are found in the Texas Business and Commerce Code and apply to any person or business that conducts business in Texas and owns or licenses computerized data containing sensitive personal information.

"A person who conducts business in this state and owns or licenses computerized data that includes sensitive personal information shall disclose any breach of system security... to any individual whose sensitive personal information was, or is reasonably believed to have been, acquired by an unauthorized person."Tex. Bus. & Com. Code § 521.053(b)

4. Notifying Affected Individuals

Disclosure to affected individuals must be made without unreasonable delay and, in any case, no later than the 60th day after the business determines a breach occurred, with limited exceptions for law enforcement investigations or the time needed to determine the scope of the breach.

The 60-day clock starts running after the business determines a breach occurred, not merely when a breach is first suspected.

5. Notifying the Texas Attorney General

If a breach affects 250 or more Texas residents, the business must also notify the Texas Attorney General. Texas law requires this notification as soon as practicable and no later than the 30th day after the business determines that the breach occurred.

"A person... shall notify the attorney general of that breach as soon as practicable and not later than the 30th day after the date on which the person determines that the breach occurred, if the breach involves at least 250 residents of this state."Tex. Bus. & Com. Code § 521.053(i)
Info Since September 1, 2023, all Attorney General breach notifications must be submitted electronically through the official form on the Texas Attorney General's website.

6. What Counts as Sensitive Personal Information

Sensitive personal information under Texas breach-notification law generally includes a person's name combined with a Social Security number, driver's license number, or financial account number, as well as certain health and biometric information. Understanding what qualifies is essential to determining whether an incident triggers the notification requirement at all.

7. Biometric Data in Texas: An Overview

As biometric identifiers — fingerprints, facial recognition, retinal scans, and voiceprints — become more common in commercial settings such as employee timekeeping and building access, Texas businesses need to understand the specific rules governing their capture and use, both under CUBI and, where applicable, the TDPSA's sensitive-data provisions.

8. The Capture or Use of Biometric Identifier Act (CUBI)

CUBI, codified in Chapter 503 of the Texas Business and Commerce Code, regulates how businesses may capture and use biometric identifiers for commercial purposes.

"'Biometric identifier' means a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry. A person may not capture a biometric identifier of an individual for a commercial purpose unless the person informs the individual before capturing the identifier and receives the individual's consent."Tex. Bus. & Com. Code § 503.001(a)–(b)
2026 Update Effective January 1, 2026, amendments to CUBI enacted through House Bill 149 (the Texas Responsible Artificial Intelligence Governance Act) added provisions addressing biometric identifiers associated with images or other media available on the internet or from other publicly available sources. Under the amended statute, the mere existence of such an image or media does not, by itself, establish notice or consent unless the individual made the image or media publicly available themselves. The amendment also added exemptions for certain AI model training and development activities and for AI systems used to prevent or investigate security incidents, identity theft, fraud, or harassment, unless the system is used or deployed to uniquely identify a specific individual.
CUBI's Notice, Consent, and Destruction Requirements

CUBI's Notice, Consent, and Destruction Requirements

Requirement What It Means
Notice Individual must be informed before capture.
Consent Individual must affirmatively consent before capture.
No sale/disclosure Restricted, with limited statutory exceptions.
Destruction Required within a reasonable time after the purpose for collection expires, and no later than the first anniversary of the date that purpose expires, subject to statutory exceptions.
Financial institution exemption Voiceprint data held by financial institutions is excluded.
Warning Employers using fingerprint or facial recognition systems for timekeeping or security should provide the required notice and obtain consent before employees are enrolled. Maintaining documentation of the notice and consent process can also help demonstrate compliance — retrofitting compliance after a system is already in use is far more difficult.

10. CUBI Penalties and Enforcement

CUBI does not create a private right of action — individuals cannot sue directly under the statute. Instead, enforcement is handled exclusively by the Texas Attorney General.

"A person who violates this section is subject to a civil penalty of not more than $25,000 for each violation. The attorney general may bring an action to recover the civil penalty."Tex. Bus. & Com. Code § 503.001(d)

11. Industry-Specific Requirements

Healthcare (HIPAA)

Additional safeguards apply to protected health information, including biometric data used for patient identification. HIPAA-regulated entities are also generally exempt from the TDPSA.

Financial Services (GLBA)

Financial institutions must implement information security programs to protect nonpublic customer information, and are generally exempt from the TDPSA under the Gramm-Leach-Bliley Act carve-out.

Payment Processing

Businesses that accept payment cards may also need to comply with applicable PCI DSS requirements — a private payment-card industry security standard rather than a government statute — for storing and transmitting card data.

Employers Using Biometrics

Timekeeping or access-control systems using fingerprints or facial recognition must comply with CUBI's notice and consent rules regardless of industry.

12. Data Security Best Practices

Beyond the specific statutory requirements, Texas businesses benefit from implementing comprehensive data security programs, including regular security assessments and penetration testing, employee training on security and privacy practices, and maintaining cyber insurance coverage appropriate to the business's risk profile.

Better Practice

Conduct a data inventory identifying exactly what sensitive personal information and biometric data your business collects, where it's stored, and who has access — this single step makes both breach response and CUBI/TDPSA compliance dramatically easier.

13. Building an Incident Response Plan

Developing an incident response plan before a breach occurs — rather than improvising one under time pressure — helps ensure the business can meet Texas's 60-day and 30-day notification deadlines and reduces the risk of a rushed, incomplete response.

14. Common Mistakes

Mistake

Missing the 30-Day AG Notification Deadline

Businesses sometimes assume the 60-day individual-notice deadline also applies to Attorney General notification, missing the shorter 30-day requirement for breaches affecting 250+ residents.

Mistake

Capturing Biometric Data Without Notice and Consent

Rolling out fingerprint or facial recognition systems without first providing the required notice and obtaining consent creates direct CUBI exposure.

Mistake

No Retention or Destruction Policy for Biometric Data

CUBI requires destruction within a reasonable time and no later than the first anniversary of the date the purpose expires — indefinitely retaining biometric identifiers increases legal risk.

Mistake

Assuming the TDPSA Doesn't Apply

Some businesses assume Texas has no general privacy law and overlook TDPSA obligations entirely — an increasingly costly mistake given active Attorney General enforcement.

Mistake

Treating Breach Notification as a One-Size-Fits-All Process

Failing to distinguish between the individual-notice and AG-notice requirements — including their different deadlines and thresholds — can lead to incomplete compliance.

Mistake

No Incident Response Plan in Place Before a Breach

Scrambling to build a response process after a breach has already occurred often causes businesses to miss statutory deadlines.

Mistake

Overlooking Layered Industry-Specific Obligations

Businesses in healthcare, finance, or payment processing sometimes address Texas requirements without recognizing that HIPAA, GLBA, or applicable PCI DSS standards impose separate, additional obligations.

15. Compliance Checklist

  • Determine whether the business qualifies for the TDPSA's small-business exemption, and confirm sensitive-data-sale consent requirements even if exempt.
  • Data inventory identifies all sensitive personal information and biometric data collected.
  • Notice and consent process in place before capturing any biometric identifier.
  • Destruction schedule established for biometric identifiers, no later than the first anniversary of the date the collection purpose expires.
  • Incident response plan drafted and tested before a breach occurs.
  • Process in place to notify affected individuals within 60 days of a determined breach.
  • Process in place to notify the Texas Attorney General within 30 days for breaches affecting 250+ residents.
  • Electronic AG notification form procedures understood and ready to use.
  • Industry-specific obligations (HIPAA, GLBA, applicable PCI DSS standards) mapped to the business's operations.
  • Employee training on data security conducted regularly.
  • Cyber insurance coverage evaluated against the business's actual risk exposure.

16. Primary Government Sources

17. Frequently Asked Questions

Does Texas have a comprehensive data privacy law?

Yes. The Texas Data Privacy and Security Act (TDPSA), effective July 1, 2024, is Texas's comprehensive consumer data privacy law. It gives Texas consumers rights to access, correct, delete, and opt out of certain processing of their personal data, and requires covered businesses to implement reasonable data security practices.

What is the Texas Data Privacy and Security Act?

The TDPSA, codified at Texas Business and Commerce Code Chapter 541, regulates how businesses collect, use, process, and sell Texas consumers' personal data. It grants consumer rights such as access, correction, deletion, and opt-out, requires clear privacy notices and reasonable security measures, and is enforced exclusively by the Texas Attorney General.

Does the Texas Data Privacy and Security Act apply to small businesses?

Small businesses, as defined by the U.S. Small Business Administration, are generally exempt from the TDPSA. However, even an exempt small business must still obtain consumer consent before selling sensitive personal data.

How quickly must a Texas business notify individuals after a data breach?

Notification must be made without unreasonable delay and no later than the 60th day after the business determines a breach occurred, subject to limited exceptions.

When must the Texas Attorney General be notified of a breach?

If the breach affects 250 or more Texas residents, the Attorney General must be notified as soon as practicable and no later than 30 days after the business determines the breach occurred.

Does Texas have a biometric privacy law like Illinois's BIPA?

Texas has its own biometric statute, CUBI, but it is narrower than Illinois's BIPA in some respects — most notably, CUBI does not create a private right of action, so individuals cannot sue directly under the statute.

What counts as a biometric identifier under Texas law?

CUBI defines a biometric identifier as a retina or iris scan, fingerprint, voiceprint, or record of hand or face geometry.

Do I need consent before using fingerprint timeclocks for employees?

Yes. Under CUBI, employers must inform employees before capturing their biometric identifiers and obtain consent, even for routine uses like timekeeping.

What are the penalties for violating CUBI?

Civil penalties of up to $25,000 per violation, which may only be pursued by the Texas Attorney General.

Can an individual sue a business directly under CUBI or the TDPSA?

Neither CUBI nor the TDPSA provides a private right of action under the statute. The Texas Attorney General has enforcement authority under both laws.

How long can a business keep biometric data it collects?

CUBI requires that captured biometric identifiers be destroyed within a reasonable time after the purpose for collecting them expires, and no later than the first anniversary of that expiration date, subject to limited statutory exceptions.

Are financial institutions exempt from CUBI or the TDPSA?

Voiceprint data retained by financial institutions or their affiliates is specifically exempt from CUBI's requirements. Separately, entities regulated under the Gramm-Leach-Bliley Act are generally exempt from the TDPSA.

What should a business do immediately after discovering a data breach?

Begin an investigation to determine the scope of the breach, consult legal counsel, and prepare to meet the applicable 60-day individual notification and, if applicable, 30-day Attorney General notification deadlines.

SB

Smart Business Blueprint Research Team

Smart Business Blueprint is not a law firm or accounting firm and does not provide tax, legal, or accounting services. Content is prepared for general educational purposes based on publicly available Texas statutes and government sources, and is reviewed periodically for accuracy.

It is not a substitute for advice from a licensed Texas attorney familiar with your specific situation.

Data security and biometric privacy law change frequently at both the state and federal level. Confirm current requirements and deadlines with a licensed attorney before responding to an actual incident.
SHARE

Website Terms of Use and Privacy Policies for Texas Businesses

Trademark Registration in Texas vs. Federal Registration